Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-33322 MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusio… Minio 2026-03-17t21-25-16z+ Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-33768 Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path header and x_astro_path query par… \@astrojs\/vercel 10.0.2+ Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-33409 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.52 and 9.6.0-alpha.41, … Parse Server 8.6.52 / 9.6.0+ Fix from $2,3002026-03-24 CRITICAL 9.3 CVE-2026-2417 A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthe… Mitigation only Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-33407 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY a… Wallos 4.7.0+ Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-33340EPSS 22% LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulner… Lollms Web Ui No fix yet Fix from $2,3002026-03-24 CRITICAL 9.6 CVE-2026-33334 Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron w… Vikunja 2.2.2+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4729 Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 149.0+ Fix from $2,3002026-03-24 CRITICAL 10.0 CVE-2026-4725 Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. Firefox 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-4724 Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. Firefox 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4723 Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. Firefox 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4721 Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showe… Firefox 115.34.0 / 140.9.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4720 Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4717 Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 14… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-4716 Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-4715 Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunde… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4711 Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4710 Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thun… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4705 Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4702 JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4701 Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 1… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4700 Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4698 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thund… Firefox 115.34.0 / 140.9.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4696 Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbi… Firefox 115.34.0 / 140.9.0+ Fix from $2,3002026-03-24 CRITICAL 10.0 CVE-2026-4692 Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbi… Firefox 115.34.0 / 140.9.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4691 Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thun… Firefox 115.34.0 / 140.9.0+ Fix from $2,3002026-03-24 CRITICAL 10.0 CVE-2026-4689 Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ES… Firefox 115.34.0 / 140.9.0+ Fix from $2,3002026-03-24 CRITICAL 10.0 CVE-2026-4688 Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunder… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-33475 Langflow is a tool for building and deploying AI-powered agents and workflows. An unauthenticated remote shell injection vulnerability exists in mult… Langflow 1.9.0+ Fix from $2,3002026-03-24 CRITICAL 9.9 CVE-2026-33309EPSS 11% Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-6… Langflow 1.9.0+ Fix from $2,3002026-03-24